The following warnings occurred:
Warning [2] Undefined array key "lockoutexpiry" - Line: 94 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 94 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined array key "lockoutexpiry" - Line: 568 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 568 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined variable $can_access_moderationqueue - Line: 744 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 744 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined array key "avatartype" - Line: 884 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 884 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined array key "avatartype" - Line: 884 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 884 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined variable $awaitingusers - Line: 34 - File: global.php(951) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/global.php(951) : eval()'d code 34 errorHandler->error
/global.php 951 eval
/showthread.php 28 require_once
Warning [2] Undefined array key "style" - Line: 1016 - File: global.php PHP 8.2.16 (Linux)
File Line Function
/global.php 1016 errorHandler->error
/showthread.php 28 require_once
Warning [2] Undefined property: MyLanguage::$lang_select_default - Line: 5196 - File: inc/functions.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions.php 5196 errorHandler->error
/global.php 1016 build_theme_select
/showthread.php 28 require_once
Warning [2] Undefined array key "additionalgroups" - Line: 7360 - File: inc/functions.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions.php 7360 errorHandler->error
/inc/functions.php 5216 is_member
/global.php 1016 build_theme_select
/showthread.php 28 require_once
Warning [2] Undefined array key "mybb" - Line: 1997 - File: inc/functions.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions.php 1997 errorHandler->error
/inc/functions_indicators.php 41 my_set_array_cookie
/showthread.php 669 mark_thread_read
Warning [2] Undefined property: MyLanguage::$ratings_update_error - Line: 5 - File: showthread.php(772) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/showthread.php(772) : eval()'d code 5 errorHandler->error
/showthread.php 772 eval
Warning [2] Undefined array key "additionalgroups" - Line: 7360 - File: inc/functions.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions.php 7360 errorHandler->error
/inc/functions_user.php 816 is_member
/inc/functions_post.php 416 purgespammer_show
/showthread.php 1124 build_postbit
Warning [2] Undefined array key "profilefield" - Line: 6 - File: inc/functions_post.php(484) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/inc/functions_post.php(484) : eval()'d code 6 errorHandler->error
/inc/functions_post.php 484 eval
/showthread.php 1124 build_postbit
Warning [2] Undefined array key "showimages" - Line: 757 - File: inc/functions_post.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions_post.php 757 errorHandler->error
/showthread.php 1124 build_postbit
Warning [2] Undefined array key "showvideos" - Line: 762 - File: inc/functions_post.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions_post.php 762 errorHandler->error
/showthread.php 1124 build_postbit
Warning [2] Undefined array key "showimages" - Line: 800 - File: inc/functions_post.php PHP 8.2.16 (Linux)
File Line Function
/inc/functions_post.php 800 errorHandler->error
/showthread.php 1124 build_postbit
Warning [2] Undefined array key "invisible" - Line: 1565 - File: showthread.php PHP 8.2.16 (Linux)
File Line Function
/showthread.php 1565 errorHandler->error
Warning [2] Undefined variable $threadnotesbox - Line: 33 - File: showthread.php(1597) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/showthread.php(1597) : eval()'d code 33 errorHandler->error
/showthread.php 1597 eval
Warning [2] Undefined variable $addremovesubscription - Line: 82 - File: showthread.php(1597) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/showthread.php(1597) : eval()'d code 82 errorHandler->error
/showthread.php 1597 eval
Warning [2] Undefined variable $thread_deleted - Line: 104 - File: showthread.php(1597) : eval()'d code PHP 8.2.16 (Linux)
File Line Function
/showthread.php(1597) : eval()'d code 104 errorHandler->error
/showthread.php 1597 eval




Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Do you still browse like a 60 year old? Check yo shit.
#1
Quote:Oh god, MMO-Champion got hacked
by Boubouille on on May 21, 2010, 09:12:24 pm
Update - Huh, yeah, you had a message pointing to http://www.agoragames.com/ while the site was down. They're the very awesome and comprehensive techs in charge of MMO-Champion, the site was perfectly safe. The site database was also safe and none of your passwords are compromised here, it's really just a few JS files changed, and worst case scenario you are very unlucky and got a spyware that won't affect your WoW account.

I'm just very serious when it comes to security and had no plan to hide the problem. (Even if I'm probably overreacting)

Oh god, MMO-Champion got hacked
Yay! It finally happened! MMO-Champion got hacked! But don't worry too much, the title is mostly here to scare you and make sure you will read the rest. The site got indirectly affected by a very nasty virus called Gumblar, the site is cached in various ways and it means that most users are potentially safe but I strongly suggest that you read the entire post.

Gumblar, AKA Troj/JSRedir-R, is a botnet driven virus which attacks both websites and normal computers. Sounds scary, and to anyone who owns their own website it is, but to anyone else it's mostly harmless.

How does it work?
The virus is split into two parts. There's a javascript version, which infects websites, and the actual virus itself which infects computers. Whenever a browser executes the javascript on a website, it runs a Java applet and (through a Java exploit or two) installs the virus onto your computer. The virus, once warm and snug on a computer, looks for any FTP details you may have stored (In dreamweaver, filezilla, pretty much any FTP application) and makes a copy of them.

For every FTP it manages to get, it attempts to make a connection and then infects the website with the javascript. It does this by opening .js/.html/.php files and attaching a unique version of itself to a position inside the file, usually at the end. This new code is unique per website, not per file, so removing it isn't as daunting as it sounds.

In addition to spreading itself to every website it can get its claws on, the virus also reprises its role as a traditional Trojan and attempts to install other spyware onto your computer, including redirecting popular websites (such as Google) to its own unsafe alternative.

How do I know if I have it? How do I get rid of it?
Most modern anti-viruses should pick up the Gumblar virus. Personally I'd suggest downloading and installing Malwarebytes and doing a complete system scan. Make absolute sure your anti-virus is up to date before scanning, and make sure it's on a full/intensive scan, take no risks with a quick sweep.

For webmasters, there's a lovely tool called Unmask Parasites for checking if your website is safe or not. However, if you suspect you may have been infected but this tool returns nothing, you may be best suited to manually look through the files. Open up a few random .js files, and look at the end for a line or two of code that you don't recognise. Open up some .html files for a <script> tag that shouldn't be there. If you find it, take your website down immediately and start removing it. If you have backups, make sure they're clean and restore them. Otherwise, you can manually fix the files. Automated tools do not work so well for this as it's unique code for every website.

As always, it is recommended you change any private details (such as passwords) after you have confirmed you are safe. While World of Warcraft/Battlenet accounts are not effected by this virus, it is still strongly advised you change your password for it regardless.

My epics are safe?
Gumblar is a botnet driven virus, which means the infection process is entirely automated by other infected machines, no human intervention. As it was not designed to look for World of Warcraft details, it is not particularly interested in looking for them. This doesn't mean you can slack and use this as an excuse to never change your password though. It's always a good time to change your password!

Technical details
For more details about Gumblar, see this Wikipedia article or this Unmask Parasites article. For a technical summary of Gumblar, there's a nice article on iss.net about it.
[Image: WZpEFp9.gif?1]
[Image: NEsPq.gif]
[Image: 56jYs.gif]
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)